What's changed: Initial version
4.2System Audit and Service Management
Learn the flow of system audit, in which an independent third party evaluates information systems, and its relationship to internal control; ITIL and the SLA (service level agreement) that underpin the continuous operation of IT services; availability management, which keeps systems running, and capacity management, which prepares for future load; and how audit evidence (logs) is handled as the basis for an audit.
Information security does not end once controls are put in place—it requires an independent party to confirm those controls actually work, and continuous maintenance through day-to-day operations. Here we cover two pillars: system audit, the mechanism for evaluation, and service management, which sustains operations.
4.2.1System audit flow and internal control
- System audit is an activity in which an independent system auditor verifies whether risk management and internal control related to information systems are functioning effectively, following the flow audit planning -> preliminary survey -> main survey -> evaluation/conclusion -> reporting -> follow-up. Independence from the audited department is the premise for its credibility.
- Internal control is the set of mechanisms (segregation of duties, approval processes, monitoring, etc.) that management itself establishes and operates to ensure business is conducted properly. A system audit is the activity that checks, from outside (or an independent internal audit function), whether internal control is functioning effectively—a distinct role from internal control itself.
4.2.2ITIL and SLA
- ITIL (Information Technology Infrastructure Library) is a collection of best practices for IT service management. It systematizes the service lifecycle from planning through design, transition, operation, and improvement, providing common concepts and terminology for delivering stable service.
- An SLA (Service Level Agreement) is a document in which a service provider and its user (or the party outsourcing) agree on numeric quality targets such as uptime, response time, and incident-recovery time. It is also used as a means to evaluate and secure a supplier's security management level, and it is considered desirable to also agree on what happens if a target is missed (penalties, improvement plans).
4.2.3Availability/capacity management and evidence
- Availability management maintains a system so it is usable whenever and to the extent needed (redundancy, failure monitoring, established recovery procedures). Capacity management plans and reinforces performance and capacity in anticipation of future growth in usage or peak load. Because insufficient capacity leading to degraded performance or downtime directly reduces availability, the two are closely related.
- An audit evidence log records the history of a system's operations, access, and processing, serving as objective evidence backing up the effectiveness of a system audit or internal control. If logs can be tampered with or deleted, the audit itself loses its footing, so protecting log integrity (append-only storage, separation of access rights, etc.) is itself tested as an important control.
The staples: a system auditor must be independent of the audited target; management establishes and operates internal control, while a system audit verifies it; an SLA is a document agreeing on quality levels as numeric targets; and protecting log integrity is indispensable as audit evidence. Questions probing the order of the system-audit flow (planning -> preliminary survey -> main survey -> evaluation/reporting -> follow-up) are also standard.
Consider mid-size service company D, which outsources operation of its core system to an external cloud provider. D's internal audit function drew up an annual system audit plan and first conducted a preliminary survey, collecting documentation on the provider's operating structure and how it manages access privileges. In the following main survey, actual access logs and change-management records were extracted to confirm no unapproved configuration change had occurred. At this stage, the auditors also checked how the provider's audit evidence log was stored—confirming it had not been tampered with by verifying transfer to append-only storage and separation of administrators' delete privileges. The audit found that the provider's SLA-defined uptime target of 99.9% had been missed in one month over the past year; investigation revealed that capacity management anticipating peak-season access concentration had been inadequate, straining server resources and reducing availability as a result. The auditors documented this as a finding and conducted follow-up, requiring the provider to "reinforce capacity ahead of anticipated access peaks" and "formalize an improvement plan for missed SLA targets." This whole process verified, from an independent auditor's standpoint, whether D's own internal control (the approval process for selecting and contracting with the provider) was functioning effectively—a good illustration of the distinct roles of internal control itself and a system audit.
| Term | Who performs it | Role |
|---|---|---|
| Internal control | Established/operated by management | The mechanism itself ensuring proper operations |
| System audit | Independent auditor | Verifies internal control is functioning effectively |
| SLA | Agreed by provider and user | Formalizes quality levels as numeric targets |
| Audit evidence (logs) | Automatically recorded by the system | Evidence backing the effectiveness of the audit/internal control |
Trap: "Internal control and a system audit are just different names for the same activity" is wrong. Internal control is the mechanism itself, established and operated by management, while a system audit is the activity that verifies, from an independent standpoint, whether it is functioning effectively—a genuine difference in role. Also, "it is efficient for staff in the audited department to audit their own department" is wrong—it undermines independence and destroys the audit's credibility. Furthermore, "an SLA is a technical specification, not a legally binding agreement" is wrong—an SLA is an agreement between the provider and the user (or the outsourcing party), and missing it can trigger contractual consequences such as penalties.
4.2.4Section summary
- Internal control is the mechanism itself, established/operated by management. A system audit is the activity by which an independent auditor verifies its effectiveness
- An SLA is a document agreeing on quality levels as numeric targets. Availability management and capacity management are closely linked (insufficient capacity reduces availability)
- Protecting the integrity of audit evidence (logs) is an indispensable control underpinning the credibility of an audit
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. Which activity has an independent party verify whether risk management and internal control related to information systems are functioning effectively?
Q2. It was found that the outsourced cloud provider's uptime fell below the contractually defined 99.9% target in one month over the past year. In which document is this uptime target formally documented?
Q3. During a system audit, which of the following should the auditor especially verify regarding access logs submitted by the audited department?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

